Описание
Security update for ntfs-3g_ntfsprogs
This update for ntfs-3g_ntfsprogs fixes the following issues:
Security issues fixed:
- CVE-2019-9755: Fixed a heap-based buffer overflow which could lead to local privilege escalation (bsc#1130165).
Список пакетов
SUSE Linux Enterprise Desktop 12 SP3
libntfs-3g84-2013.1.13-5.6.1
ntfs-3g-2013.1.13-5.6.1
ntfsprogs-2013.1.13-5.6.1
SUSE Linux Enterprise Desktop 12 SP4
libntfs-3g84-2013.1.13-5.6.1
ntfs-3g-2013.1.13-5.6.1
ntfsprogs-2013.1.13-5.6.1
SUSE Linux Enterprise Software Development Kit 12 SP3
libntfs-3g-devel-2013.1.13-5.6.1
libntfs-3g84-2013.1.13-5.6.1
SUSE Linux Enterprise Software Development Kit 12 SP4
libntfs-3g-devel-2013.1.13-5.6.1
libntfs-3g84-2013.1.13-5.6.1
SUSE Linux Enterprise Workstation Extension 12 SP3
libntfs-3g84-2013.1.13-5.6.1
ntfs-3g-2013.1.13-5.6.1
ntfsprogs-2013.1.13-5.6.1
SUSE Linux Enterprise Workstation Extension 12 SP4
libntfs-3g84-2013.1.13-5.6.1
ntfs-3g-2013.1.13-5.6.1
ntfsprogs-2013.1.13-5.6.1
Ссылки
- Link for SUSE-SU-2019:1000-1
- E-Mail link for SUSE-SU-2019:1000-1
- SUSE Security Ratings
- SUSE Bug 1130165
- SUSE CVE CVE-2019-9755 page
Описание
An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to cause a heap buffer overflow, resulting in a crash or the ability to execute arbitrary code. In installations where /bin/ntfs-3g is a setuid-root binary, this could lead to a local escalation of privileges.
Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP3:libntfs-3g84-2013.1.13-5.6.1
SUSE Linux Enterprise Desktop 12 SP3:ntfs-3g-2013.1.13-5.6.1
SUSE Linux Enterprise Desktop 12 SP3:ntfsprogs-2013.1.13-5.6.1
SUSE Linux Enterprise Desktop 12 SP4:libntfs-3g84-2013.1.13-5.6.1
Ссылки
- CVE-2019-9755
- SUSE Bug 1130165